mcp-server-fetch: `fetch` prompt returns JSON-RPC error code 0 with the raw exception text for an invalid URL
Maintainer thường phản hồi trong vòng 1 ngày
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 78/100
Hướng nghiên cứu
Bắt đầu trong server.py tại các dòng 127 và 262-288, sau đó tái hiện yêu cầu prompts/get với URL không hợp lệ được nêu trong issue. So sánh cách xử lý prompt với việc xác thực mô hình Fetch được công cụ sử dụng và xác minh rằng đầu vào không hợp lệ trả về JSON-RPC -32602 cùng một thông báo rõ ràng, trong khi các URL hợp lệ vẫn trả về nội dung trang.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Describe the bug
The fetch tool validates url through the Fetch model, so a malformed URL comes back as a normal isError: true result. The fetch prompt passes arguments["url"] straight to fetch_url (server.py:262-265) and catches only McpError (server.py:267). fetch_url converts only httpx.HTTPError (server.py:127), and httpx.InvalidURL is not an HTTPError, so it escapes both handlers. With raise_exceptions=False (server.py:288), the SDK's low-level server then answers with a JSON-RPC error whose code is 0 and whose message is the raw exception text.
To Reproduce
mcp-server-fetch 0.6.3 (commit f46d957), mcp 1.29.0 (as in uv.lock), Python 3.14, Windows 11. After initialize, send over stdio:
{"jsonrpc": "2.0", "id": 3, "method": "prompts/get", "params": {"name": "fetch", "arguments": {"url": "http://[::1"}}}
Response:
{"jsonrpc": "2.0", "id": 3, "error": {"code": 0, "message": "Invalid port: ':1'"}}
The same URL through the tool is handled cleanly:
{"jsonrpc": "2.0", "id": 4, "method": "tools/call", "params": {"name": "fetch", "arguments": {"url": "http://[::1"}}}
isError: true — "1 validation error for Fetch\nurl\n Input should be a valid URL, invalid IPv6 address ..."
Expected behavior
An invalid prompt argument should produce a proper parameter error (-32602, INVALID_PARAMS) with a clear message, consistent with the tool. Code 0 is the SDK's generic fallback for unhandled exceptions, so a client can't tell a bad argument from a server fault.
Suggested fix
Validate the prompt's url the same way the tool does before fetching:
url = arguments["url"] # current code; replace with:
try:
url = str(Fetch(url=arguments["url"]).url)
except ValueError as e:
raise McpError(ErrorData(code=INVALID_PARAMS, message=str(e)))
With this change, the request above returns -32602 with the validation message, and a valid URL still returns the page content (checked locally).
Additional context
Related: #3359 / #3515 (malformed input handling). I found this while testing a static checker for MCP error handling, then reproduced it by hand with a raw JSON-RPC client (no MCP client library involved). Happy to open a PR with this change if that's useful.
- Ngôn ngữ chính
- TypeScript
- Star
- 91k
- Fork
- 11.8k
- Merge trung bình
- 6 giờ 47 phút
- Pull request đã merge (30 ngày)
- 74
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của modelcontextprotocol/servers
-
git: git_create_branch is marked non-destructive but silently resets an existing packed branchĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
modelcontextprotocol/servers#5059 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
CLAUDE.md: tool-naming rule (kebab-case) disagrees with filesystem and memory serversCó thể đã có người làm @liang0417 đã nhận 7 ngày trước. Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
modelcontextprotocol/servers#4892 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Filesystem README recommends deprecated MCP Roots protocol for restricting directory accessCó thể đã có người làm @its-amann đã nhận 12 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
modelcontextprotocol/servers#4844 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Docs: `fetch` installs npm packages during a tool call, which is worth stating for deploymentsCó thể đã có người làm @teddiesloco đã nhận 16 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
modelcontextprotocol/servers#4830 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Docs: tool descriptions for browser-embedding servers do not mention the browser's own background trafficCó thể đã có người làm @AbhiPra24 đã nhận 13 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
modelcontextprotocol/servers#4829 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của modelcontextprotocol/servers
Issue tương tự
-
feat(subscription): add Manage Subscription (Stripe portal) to the Subscription tab plan cardĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
[Feature] 通知栏合并重复消息并显示次数Đang mởarea:ui enhancement issue-form:feature platform:cross-platform review: high
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
1lck/Lithe-IDEA#1092 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
developmentseed/deck.gl-raster#693 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
Marker-Inc-Korea/AutoRAG#1801 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
iii-hq/iii#2278 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày